Weaknesses of type CWE-200

5,020 results

Exposição de Informação Sensível

A aplicação expõe dados sensíveis (senhas, tokens, PII, chaves de API) a usuários ou processos que não deveriam ter acesso. Pode acontecer por falta de controle de acesso, logs inadequados, cache inseguro ou erro na filtragem de respostas. O risco é direto: um atacante rouba credenciais, identidades ou segredos da aplicação.

Example

Um endpoint retorna a lista completa de usuários com hashes de senha em resposta JSON, ou um arquivo de backup fica exposto publicamente no servidor web contendo variáveis de ambiente com conexão ao banco de dados.

How to mitigate

Implemente controle de acesso (RBAC/ABAC), nunca exponha dados sensíveis em logs ou respostas de erro, use criptografia em trânsito e em repouso, aplique princípio do menor privilégio, e realize auditorias regulares de quais dados cada endpoint retorna.

CVE-2018-9379MEDIUMIn multiple functions of MiniThumbFile.java, there is a possible way to view the thumbnails of deleted photos due to a confused deputy. ThisEPSS 0.1%CVE-2022-33699LOWExposure of Sensitive Information in getDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via lEPSS 0.1%CVE-2022-33687LOWExposure of Sensitive Information in telephony-common.jar prior to SMR Jul-2022 Release 1 allows local attackers to access IMSI via log.EPSS 0.1%CVE-2022-33698LOWExposure of Sensitive Information in Telecom application prior to SMR Jul-2022 Release 1 allows local attackers to access ICCID via log.EPSS 0.1%CVE-2022-33700LOWExposure of Sensitive Information in putDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via lEPSS 0.1%CVE-2022-33693LOWExposure of Sensitive Information in CID Manager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid via log.EPSS 0.1%CVE-2025-58305MEDIUMIdentity authentication bypass vulnerability in the Gallery app. Impact: Successful exploitation of this vulnerability may affect service coEPSS 0.1%CVE-2021-25486LOWExposure of information vulnerability in ipcdump prior to SMR Oct-2021 Release 1 allows an attacker detect device information via analyzing EPSS 0.1%CVE-2025-22430MEDIUMIn isInSignificantPlace of multiple files, there is a possible way to access sensitive information due to a missing permission check. This cEPSS 0.1%CVE-2025-48642MEDIUMIn jump_to_payload of payload.rs, there is a possible information disclosure due to a logic error in the code. This could lead to local infoEPSS 0.1%CVE-2022-24001LOWInformation disclosure vulnerability in Edge Panel prior to Android S(12) allows physical attackers to access screenshot in clipboard via EdEPSS 0.1%CVE-2024-45447MEDIUMAccess control vulnerability in the camera framework module Impact: Successful exploitation of this vulnerability may affect service confideEPSS 0.1%CVE-2025-68959MEDIUMPermission verification bypass vulnerability in the media library module. Impact: Successful exploitation of this vulnerability may affect sEPSS 0.1%CVE-2021-25519MEDIUMAn improper access control vulnerability in CPLC prior to SMR Dec-2021 Release 1 allows local attackers to access CPLC information without pEPSS 0.1%CVE-2025-68966MEDIUMPermission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect service confidentiaEPSS 0.1%CVE-2026-76735MEDIUMAuthenticated Local Sensitive Information Disclosure in HPE Networking Instant OnEPSS 0.1%CVE-2022-30753LOWImproper use of a unique device ID in unprotected SecSoterService prior to SMR Jul-2022 Release 1 allows local attackers to get the device IEPSS 0.1%CVE-2025-58277MEDIUMPermission verification bypass vulnerability in the Camera app. Successful exploitation of this vulnerability may affect service confidentiaEPSS 0.1%CVE-2022-33728MEDIUMExposure of sensitive information in Bluetooth prior to SMR Aug-2022 Release 1 allows local attackers to access connected BT macAddress via EPSS 0.1%CVE-2023-23588MEDIUMA vulnerability has been identified in SIMATIC IPC1047 (All versions), SIMATIC IPC1047E (All versions with maxView Storage Manager < 4.09.00EPSS 0.1%